CVE-2026-86295: D-Link DIR-895L udhcpcd serverpacket.c sendACK command injection
A vulnerability was found in D-Link DIR-895L A1102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the argument Hostname results in command injection. The attack can be executed remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be executed remotely and requires no privileges or user interaction, according to the supplied severity vector. Exploitation involves manipulating the Hostname argument processed by udhcpcd's sendACK function.
How likely is exploitation in practice?
A public exploit has been reported. The vulnerability is rated high severity with a CVSS score of 8.3, and the attack complexity is listed as low.
Which device version is identified as affected?
The reported affected version is D-Link DIR-895L A1_102b07. The provided data does not identify other affected or fixed versions.